RA10
Mark Schemes
BTEC Level 3 National Extended Certificate in IT
Mark Scheme — Predicted Paper 1
Unit 1: Information Technology Systems
BTEC Level 3 National Extended Certificate in Information Technology
| Paper Reference | RA10/IT/U1/PP1 |
| Total marks | 90 |
| Series | Practice Paper — January 2027 |
This mark scheme has been prepared by RA10 for use with Predicted Paper 1. It follows the Pearson BTEC Level 3 mark scheme conventions for Unit 1 (AAQ 2025, Issue 5).
Using this mark scheme:
For short-answer questions, award the marks specified. "Accept any other appropriate/alternative response" means equivalent correct answers should be credited.
For levels-based questions, use the Level Descriptors holistically alongside the indicative content. Indicative content is not a checklist.
For revision purposes only. Not an official Pearson qualification document.
Question 1 — Online Enrolment (22 marks total)
Award one mark for each correct input device, up to a maximum of two marks.
- Keyboard (1)
- Mouse (1)
- Touchscreen (1)
- Barcode/QR scanner (1)
- Microphone (1)
Accept any other appropriate input device
Award one mark for each correct output device, up to a maximum of two marks.
- Monitor/screen (1)
- Printer (1)
- Speakers (1)
- Projector (1)
Accept any other appropriate output device
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of four marks.
- Convenient for customers (1) — payments can be made 24/7 from any device (1)
- Faster processing (1) — transactions are completed instantly online (1)
- Fewer errors (1) — details entered directly reduce transcription mistakes (1)
- Secure encryption (1) — card details are protected during transmission (1)
Accept any other appropriate/alternative response
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of four marks.
- Cost of setup/hardware/software (1) — the business must purchase new systems (1)
- Staff need training (1) — time and cost to learn the new system (1)
- Technical failure/downtime (1) — if the system or internet goes down, bookings stop (1)
- Security risk (1) — customer data could be exposed to hackers (1)
Accept any other appropriate/alternative response
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of four marks.
- Data is scrambled into ciphertext (1) so it cannot be read if intercepted (1)
- Only authorised parties with the key can decrypt it (1) protecting it during transmission (1)
- Uses protocols such as HTTPS/SSL/TLS (1) securing data over the internet (1)
Accept any other appropriate/alternative response
Indicative Content (not prescriptive — reward any well-developed point)
- Encryption — data is scrambled so it cannot be read if intercepted
- Multi-factor authentication / 2FA — a second factor (code, biometric) is required, so access is blocked even if a password is stolen
- Biometric authentication (fingerprint/facial recognition) — uses a unique physical feature so only the authorised user can log in
- Firewalls — block unauthorised network traffic
- Access control/permissions — restrict data access to authorised staff
| Level | Mark | Descriptor |
| 0 | 0 | No rewardable material. |
| 1 | 1–3 | Identifies one technique with limited explanation of how it protects data. (AO2) |
| 2 | 4–5 | Identifies two or more techniques with developed explanation of how each protects customer/patient data. (AO2/AO3a) |
| 3 | 6 | Thoroughly discusses several techniques (e.g. encryption, MFA, biometrics, firewalls) with clear explanation of how each protects data, contextualised to the organisation. (AO2/AO3a) |
Question 1 Total: 22 marks
Question 2 — Branch Network (23 marks total)
Award one mark for each correct type of operating system, up to a maximum of two marks.
- Network operating system (NOS) (1)
- Multi-tasking OS (1)
- Real-time OS (1)
- Mobile OS (1)
- Multi-user OS (1)
- Single-user OS (1)
Accept any other appropriate operating system type
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of four marks.
- File/resource sharing (1) — staff can share files and printers within the office (1)
- Centralised storage (1) — data stored on a server so staff access the same up-to-date information (1)
- Software sharing (1) — one licensed copy/network software shared by all users (1)
- Communication (1) — staff can message/email each other within the office (1)
Accept any other appropriate/alternative response
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of four marks.
- Secure remote access (1) — employees connect to the office network safely from anywhere (1)
- Encrypted connection (1) — data is protected from interception while in transit (1)
- Private tunnel over the internet (1) — traffic is hidden from unauthorised users (1)
- Cost-effective (1) — uses the public internet rather than dedicated leased lines (1)
Accept any other appropriate/alternative response
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of four marks.
- Cost (1) — the software must fit the organisation's budget (1)
- Compatibility (1) — it must work with the existing hardware/systems (1)
- Features/functionality (1) — it must meet the specific needs of the work (1)
- Security (1) — it must protect sensitive data (1)
Accept any other appropriate factor
Indicative Content (not prescriptive — reward any well-developed point)
- Open source — source code is freely available, can be modified; often free to use
- Proprietary — owned by a vendor; paid licence; support and updates provided
- Open source benefits: lower cost, community support, customisable
- Open source drawbacks: variable support, potential security concerns if not maintained
- Proprietary benefits: vendor support, reliability, regular updates
- Proprietary drawbacks: licence cost, locked into a vendor
- Suitability depends on the organisation's needs and budget
| Level | Mark | Descriptor |
| 0 | 0 | No rewardable material. |
| 1 | 1–3 | Basic understanding of open source vs proprietary. Limited comparison. (AO2) |
| 2 | 4–6 | Good evaluation. Compares open source and proprietary with several points developed in context. (AO2/AO3a) |
| 3 | 7–9 | Comprehensive evaluation. Thorough, balanced comparison covering cost, support, security, customisation and suitability, with a justified recommendation. (AO2/AO3a/AO3b) |
Question 2 Total: 23 marks
Question 3 — Remote Working (21 marks total)
Award up to six marks for a correct annotated diagram.
- Central server shown (1)
- Desktop computers shown connecting to the server (1)
- Printer (and managers' offices) shown (1)
- The mobile worker's laptop and smartphone shown (1)
- PAN between laptop and smartphone shown (1)
- Connection over the internet to the office server shown with annotations (1)
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of two marks.
- Performance/speed (1) — the connection must be fast enough for the work (1)
- Cost (1) — wired vs wireless and setup costs must suit the budget (1)
- Mobility (1) — wireless suits staff who move around (1)
- Reliability (1) — wired connections are usually more stable (1)
- Security (1) — wired is harder to intercept than wireless (1)
Accept any other appropriate factor
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of four marks.
- Unauthorised access (1) — an open network lets others join and misuse it (1)
- Eavesdropping/interception (1) — data sent over Wi-Fi can be intercepted (1)
- Weak/no encryption (1) — unprotected traffic is readable by attackers (1)
- Rogue access points (1) — attackers can set up fake hotspots (1)
Accept any other appropriate security issue
Indicative Content (not prescriptive — reward any well-developed point)
- Must comply with UK GDPR / Data Protection Act
- Lawful basis for processing and client consent
- Data kept secure, accurate and up to date
- Client rights: access, rectification, erasure, portability
- Computer Misuse Act — protection against unauthorised access
- Consequences of breach — fines, legal action, reputational damage
- Staff training and clear data policies
| Level | Mark | Descriptor |
| 0 | 0 | No rewardable material. |
| 1 | 1–3 | Basic understanding. Names legislation with limited application to the organisation's data. (AO2) |
| 2 | 4–6 | Good application. Discusses several legal requirements and how they apply to client data with some development. (AO2/AO3a) |
| 3 | 7–9 | Comprehensive evaluation. Thorough discussion of legal obligations (GDPR, Computer Misuse Act), client rights and consequences of breach, with a balanced judgement. (AO2/AO3a/AO3b) |
Question 3 Total: 21 marks
Question 4 — Cloud & Remote (24 marks total)
Award up to three marks for an accurate description of how the organisation can use a cloud computing model.
- Identifies a model (e.g. IaaS/SaaS/PaaS or cloud backup service) (1)
- Describes how data is stored on remote servers managed by a provider (1)
- Explains access over the internet rather than on-site hardware (1)
Accept any appropriate cloud model correctly described
Indicative Content (not prescriptive — reward any well-developed point)
- Infrastructure as a Service (IaaS) — rental of servers/storage; most control, most management
- Platform as a Service (PaaS) — development platform; middle level of control
- Software as a Service (SaaS) — ready-made application; least control, least management
- Private cloud — dedicated to one organisation; more secure, more costly
- Public cloud — shared provider; cheaper, less control
- Hybrid cloud — mixes private and public; balances security and cost
- For backup: public cloud/IaaS is cost-effective for large data volumes
- Security/compliance considerations for the specific organisation
- Scalability — cloud scales up/down with demand
- Cost — pay-as-you-go vs capital expenditure
| Level | Mark | Descriptor |
| 0 | 0 | No rewardable material. |
| 1 | 1–3 | Basic understanding of cloud models. Names one or two models (IaaS/PaaS/SaaS or public/private) with limited application. (AO2) |
| 2 | 4–6 | Good evaluation. Compares several cloud models and how they could meet the organisation's needs, with some development. (AO2/AO3a) |
| 3 | 7–9 | Comprehensive evaluation. Thorough comparison of multiple cloud models (service and deployment), evaluated against the organisation's needs, security, cost and scalability, with a justified recommendation. (AO2/AO3a/AO3b) |
Indicative Content (not prescriptive — reward any well-developed point)
- Remote working with VPN — secure, flexible, encrypted access from anywhere
- On-site working — direct access to the office network
- VPN benefits: flexibility, reduced travel, security via encryption
- VPN drawbacks: dependent on internet speed/reliability, needs training
- On-site benefits: reliable fast network, direct supervision, secure local data
- On-site drawbacks: less flexibility, higher premises/travel costs
- Performance and efficiency comparison
- Suitability depends on the organisation's needs
| Level | Mark | Descriptor |
| 0 | 0 | No rewardable material. |
| 1 | 1–4 | Basic understanding of remote vs on-site working. Limited comparison, mostly descriptive. (AO2) |
| 2 | 5–8 | Good evaluation comparing VPN remote working with on-site, with several points developed in context. (AO2/AO3a) |
| 3 | 9–12 | Comprehensive evaluation. Thorough, balanced comparison covering security, performance, flexibility, cost and suitability, clearly contextualised, with a justified conclusion. (AO2/AO3a/AO3b) |
Question 4 Total: 24 marks Paper Total: 90 marks